{"id":"CVE-2023-24998","title":"Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.\n\n\n\n\nNote that, like all of the fil…","summary":"Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.\n\n\n\n\nNote that, like all of the fil…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-770"],"vendor":"apache","product":"commons_fileupload","affected":["commons_fileupload >= 1.0, < 1.5","commons_fileupload = 1.0","debian_linux = 9.0","debian_linux = 11.0"],"patched":["commons_fileupload 1.5"],"published":"2023-02-20","updated":"2026-10-07","sourceUpdated":"2026-10-07T17:16:43.860","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-24998","references":[{"url":"http://www.openwall.com/lists/oss-security/2023/05/22/1","label":"security@apache.org"},{"url":"https://lists.apache.org/thread/4xl4l09mhwg4vgsk7dxqogcjrobrrdoy","label":"security@apache.org"},{"url":"https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html","label":"security@apache.org"},{"url":"https://security.gentoo.org/glsa/202305-37","label":"security@apache.org"},{"url":"https://www.debian.org/security/2023/dsa-5522","label":"security@apache.org"},{"url":"http://www.openwall.com/lists/oss-security/2023/05/22/1","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread/4xl4l09mhwg4vgsk7dxqogcjrobrrdoy","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2025/07/msg00008.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202305-37","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20230302-0013/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20241108-0002/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2023/dsa-5522","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org","exploit-available"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2025-06-03T19:22:53.244328Z"},"epss":0.48788,"epssPercentile":0.98847,"exploits":{"github":1,"githubRepos":["https://github.com/nice1st/CVE-2023-24998"],"checkedAt":"2026-10-07T17:41:11.301Z"},"exploitAvailable":true,"ingestedAt":"2026-10-07T16:38:22.239Z","slug":"CVE-2023-24998","body":"## Overview\n\nApache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.\n\n\n\n\nNote that, like all of the file upload limits, the\n          new configuration option (FileUploadBase#setFileCountMax) is not\n          enabled by default and must be explicitly configured.\n\n## Affected\n\n- `commons_fileupload >= 1.0, < 1.5`\n- `commons_fileupload = 1.0`\n- `debian_linux = 9.0`\n- `debian_linux = 11.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `commons_fileupload 1.5`","depth":"midnight","depthScore":63,"depthScoreParts":{"impact":41.3,"likelihood":9.8,"exploitation":12,"ransomware":0},"changes":[]}